Are you thinking of the CRL for the certificate bound to the IP-HTTPS listener? There's no problem with the internal clients being able to reach that CDP, in fact, you'll need that to support NLS.
The Test Lab Guide CRL Check Update post was referring to the original TLG. Use the one based on the TLG format that I created for UAG SP1 RC.
Thanks!
Tom